<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif;font-size:14px"><div dir="ltr" id="yui_3_16_0_1_1426708550900_425942"><span>Hi Scott,</span></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424664"><br></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663">Can I verify with you that the SP can work with an IdP that uses the "Artifact Binding" and can resolve the artefact by calling a &nbsp;soap service presented by the IdP?&nbsp;</div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><br></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663">The documentation indicates this is possible but it is an oblique reference under a title called "NativeSPBackDoor" as quoted below: &nbsp;</div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><br></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><span style="font-family: Arial, sans-serif; line-height: 20px;" class="" id="yui_3_16_0_1_1426708550900_425354"><i><font color="#cd232c">"One of the supported mechanisms takes advantage of the less-commonly used SAML binding called the "Artifact Binding". Instead of pushing a SAML response through the client, an encoded reference called an "artifact" is generated by the IdP, passed to the SP via a redirect, and then the SP turns the artifact into the SAML response using a SOAP request."</font></i></span><br></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><span style="color: rgb(51, 51, 51); font-family: Arial, sans-serif; line-height: 20px;" class=""><br></span></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><span style="color: rgb(51, 51, 51); font-family: Arial, sans-serif; line-height: 20px;" class="" id="yui_3_16_0_1_1426708550900_426542">Is there another part of the documentation that explains how to configure the above?</span></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><span style="color: rgb(51, 51, 51); font-family: Arial, sans-serif; line-height: 20px;" class=""><br></span></div><div dir="ltr" id="yui_3_16_0_1_1426708550900_424663"><span style="color: rgb(51, 51, 51); font-family: Arial, sans-serif; line-height: 20px;" class="">Regards,<br>David.</span></div>  <div dir="ltr" id="yui_3_16_0_1_1426708550900_424663" class="" style=""><br class="" style=""></div><br><div class="qtdSeparateBR"><br><br></div><div class="yahoo_quoted" style="display: block;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif; font-size: 14px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif; font-size: 16px;"> <div dir="ltr"> <font size="2" face="Arial"> On Monday, 9 March 2015 11:59 AM, "Cantor, Scott" &lt;cantor.2@osu.edu&gt; wrote:<br> </font> </div>  <br><br> <div class="y_msg_container">On 3/8/15, 6:50 PM, "David Tildesley" &lt;<a shape="rect" ymailto="mailto:davotnz@yahoo.co.nz" href="mailto:davotnz@yahoo.co.nz">davotnz@yahoo.co.nz</a>&gt; wrote:<div class="yqt7792637733" id="yqtfd38566"><br clear="none"><br clear="none">&gt;Is this achievable with "back to back" connection of Shibboleth Identity and Service Provider instances?</div><br clear="none"><br clear="none">It's achievable, but if you weren't already planning to use Apache as the web server for the IdP, it adds an additional layer. There's also no current data connector within the IdP that will pull data from the headers to use downstream, though that will get fixed in the next couple of releases.<br clear="none"><br clear="none">We didn't design the IdP to function as a gateway, and a lot of people use simpleSAML.php for that use case.<br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><div class="yqt7792637733" id="yqtfd74914"><br clear="none"></div><br><br></div>  </div> </div>  </div></div></body></html>